Threat Intelligence

Threat IntelligenceNew

A built-in Threat Intelligence Platform that ingests live IOC feeds from URLhaus, Feodo Tracker, OpenPhish, AlienVault OTX, and AbuseIPDB — enriching your security data with real-world threat context across every module.

Threat Intelligence

Live IOC feeds, enrichment, and threat lookup

What it does

Key capabilities

Live Feed Ingestion

Automatically pulls IOCs from URLhaus, Feodo Tracker botnet C2 IPs, OpenPhish, AlienVault OTX, and AbuseIPDB on a configurable schedule.

IOC Database

Maintains a searchable, filterable database of all active Indicators of Compromise — IPs, domains, URLs, and file hashes — per client.

Real-Time Lookup

Instantly check any IP, domain, URL, or hash against your live IOC database from anywhere in the platform.

Cross-Module Enrichment

TIP match badges appear automatically in HakScout, Investigations, and other modules — surfacing threat context where you need it.

Manual IOC Entry

Add custom IOCs from your own threat intelligence sources, incident findings, or vendor advisories.

IOC Dashboard

Visual dashboard showing IOC counts by type and severity, feed sync status, and recently added indicators.

Highlights

Why Threat Intelligence?

  • URLhaus, Feodo Tracker, OpenPhish — free feeds, no key required
  • AlienVault OTX and AbuseIPDB with API key
  • IOC match badges surfaced across HakScout, Investigations and more
  • Per-client IOC database — no cross-tenant data mixing
  • MERGE upserts keep IOC data current without duplication
Included in OneView

Threat Intelligence is part of the Hakware OneView platform. All findings, events, and data from this module flow into your central dashboard alongside every other security signal in your environment.

24/7 Support Available
Phone: +27 060 984 1210
FAQs

Frequently asked questions

Threat Intelligence ingests from URLhaus (malicious URLs and malware download links), Feodo Tracker (botnet command-and-control IPs), OpenPhish (active phishing URLs), AlienVault OTX (broad community threat indicators), and AbuseIPDB (abusive IP reporting). URLhaus, Feodo Tracker, and OpenPhish require no API key; OTX and AbuseIPDB use configurable keys.

Once IOCs are loaded into the platform, they are cross-referenced against live data in other modules automatically. In Hakware Scout, discovered hosts are checked against the IOC database and match badges appear on the asset record. In the Investigations module, IOC lookups query the live database. New network connections in HakObserver can trigger IOC match alerts.

Yes. The manual IOC entry form supports all common indicator types — IPv4/IPv6 addresses, domains, URLs, MD5/SHA1/SHA256 file hashes, and email addresses. You can add IOCs from internal incident findings, vendor advisories, ISAC sharing, or commercial threat intelligence subscriptions, and they receive the same cross-platform enrichment as feed-sourced indicators.

Feed ingestion schedules are configurable per feed. URLhaus, Feodo Tracker, and OpenPhish publish updates multiple times daily and Hakware ingests on a configurable interval — typically every few hours. AlienVault OTX and AbuseIPDB are polled on the same schedule. Feed sync status and last successful ingestion timestamp are visible in the IOC dashboard.

See Threat Intelligence in action

Request a personalised demo and we'll show you exactly how Threat Intelligence works within your environment.